Vulnerability Name: | CVE-2015-4715 (CCN-176734) | ||||||||||||||||
Assigned: | 2015-06-24 | ||||||||||||||||
Published: | 2015-06-24 | ||||||||||||||||
Updated: | 2020-02-28 | ||||||||||||||||
Summary: | The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values. | ||||||||||||||||
CVSS v3 Severity: | 4.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N) 4.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-552 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-4715 Source: MISC Type: Third Party Advisory, VDB Entry http://www.securityfocus.com/bid/76158 Source: XF Type: UNKNOWN owncloud-cve20154715-info-disc(176734) Source: MISC Type: Patch, Third Party Advisory https://github.com/owncloud/core/commit/bf0f1a50926a75a26a42a3da4d62e84a489ee77a Source: CCN Type: ownCloud Web site Mounted Dropbox storage allows Dropbox.com to access any file Source: CONFIRM Type: Vendor Advisory https://owncloud.org/security/advisories/mounted-dropbox-storage-allows-dropbox-com-access-file/ Source: MISC Type: Vendor Advisory https://owncloud.org/security/advisory/?id=oc-sa-2015-005 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-4715 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |